BlackHat India 2026 training

Bluetooth Low Energy security with BLESPlo.it

Bangalore

BlackHat India 2026 Conference

This intensive two-day training gives cybersecurity professionals practical, in-depth skills to analyze and exploit security weaknesses in Bluetooth Low Energy (BLE) devices. It focuses on hands-on work using real-world techniques and the trainer’s open-source BLESPlo.it toolkit.

BLESPlo.it combines a mobile application with an external ESP32-based device that extends the phone’s Bluetooth capabilities. Participants use it to clone and simulate BLE devices that behave like real hardware on the Bluetooth layer, including pairing with official apps. Device state is visible on a physical display and in mobile/web interfaces, and a dynamic scripting engine enables advanced scanning (“observer”), simulating (“peripheral”) and control (“central”) modes.

The training starts with a practical introduction to how BLE works by interacting with simulated devices. Participants explore advertising, trackers, and beacons, then write scripts for fingerprinting and decoding proprietary packet values. Next, they move to BLE connections (services, characteristics, GATT), manually controlling a sample device and quickly discovering how many products ship with little or no security. From there, they build custom BLESPlo.it control interfaces that surpass the original vendor apps with penetration testing scenarios, streamlining exploit chains.

In addition to the mobile attack options, we learn to use current Linux tools and write scripts to control and emulate devices from the console.

With the basics covered, the course progresses to passive interception and analysis of BLE traffic. Participants practice radio-layer sniffing using a hardware sniffer and learn to capture Bluetooth packets live directly on the phone and inspect them in Wireshark - without extra hardware or repeated captures.

More advanced modules include remote relays and machine-in-the-middle attacks, breaking weak pairing configurations, and reverse-engineering proprietary BLE protocols. Additional topics cover Bluetooth 5 and 6, Bluetooth Mesh, known BLE vulnerabilities, jamming, packet injection and connection hijacking, firmware-over-the-air, and essentials of BLE device development and flashing.

In the final phase, learners apply their skills to complete end-to-end security assessments of simulated targets, starting with a remote-controlled car and optionally continuing to a “perfect security” smart lock and other scenario challenges. Bringing your own device to the class is also encouraged. For those who want to go further, optional homework with the provided hardware kit and step-by-step exercises supports continued practice and skill development.

Key takeaways

  • BLE Protocol Mastery: Understand BLE advertising, GATT, pairing, and communication flows in real-world devices.
  • Practical BLE Exploitation: Perform MITM, relay attacks, pairing bypass, and protocol abuse using real tools and hardware.
  • Advanced BLE Security Testing: Use BLESPlo.it to simulate, clone, and attack BLE devices and evaluate real-world vulnerabilities.

Who should take this course

This course is designed for penetration testers, security researchers, red teamers, IoT security engineers, BLE device developers, and anyone interested in Bluetooth Low Energy and wireless security.

Audience skill level

Beginner to intermediate

Student requirements

  • No prior Bluetooth knowledge required
  • Basic Linux command line familiarity
  • Basic Python scripting knowledge recommended
  • General penetration testing or networking experience is helpful but not required

What students should bring

  • Laptop (Windows, Linux, or macOS x86-64 / Apple Silicon) with at least 50GB free space, Ability to run virtual machines, 2x USB Type-A ports or USB hub, 5GHz Wi-Fi support, Administrative privileges for USB device access in VM
  • Optional Android smartphone (up to ~8 years old acceptable)
  • Optional BLE devices for testing

What students will be provided with

  • Full course materials (PDFs, 1000+ pages)
  • Source code, binaries, and documentation
  • Pre-configured virtual machine images
  • BLESPlo.it hardware kit (BLE device, USB dongles, sniffer)

Register here:

https://www.blackhat-india.com/training-schedule#bluetooth-low-energy-security-with-blesploit-49917

comments powered by Disqus